Privacy Policy

Last updated: July 23, 2026

This page explains what VibeOpenClaw collects when you use the app, why, who we share it with, and how to get it deleted. We try to write it the way we'd want to read it: plainly, and without collecting more than we need.

What we collect

Account data: your email address and a bcrypt hash of your password (we never store your password itself). Your plan tier and subscription status, linked to a customer ID from our payment processor, Polar.sh.

Agent configuration: when you deploy an agent, we store its configuration, including any model-provider API keys you add (encrypted at rest with AES-256-GCM) and any messaging-channel bot tokens (Telegram, Discord, Slack) you connect.

Usage data:counts of API calls your agents make, for billing and plan limits. We don't currently store the content of your agent's conversations or prompts — that traffic is relayed through our server to your model provider without being written to our database.

Analytics & session replay

We use PostHog to understand how the app is used, including session replay of your interactions with the VibeOpenClaw dashboard. Password fields are masked; other on-screen text and inputs are generally not masked unless we've explicitly excluded them. We also use Google Analytics for aggregate traffic stats on the marketing site. Neither tool has access to your agent's conversation content.

Sub-processors

Third-party services that process data on our behalf:

Polar.sh

Payment processing and subscription billing. Handles your billing details and sends billing-related emails.

PostHog

Product analytics and session replay, so we can see how the app is used and fix what’s broken. Password fields are masked; most other on-screen content is not.

Google Analytics

Aggregate traffic analytics (page views, referrers) for the marketing site.

Your model provider

When you use BYOK, your agent talks directly to the LLM provider you configured (OpenAI, Anthropic, etc.) using your own key. We don’t see or store your prompts beyond what’s needed to relay the request.

Data retention

We keep your account and agent data for as long as your account is active. If you delete your account, we delete your stored data, including agent configuration and any provider keys or channel tokens on file. Billing records are retained by Polar.sh per their own retention practices.

Your choices

You can update or remove your agent's provider keys and channel tokens at any time from the dashboard. To request a copy of your data or full account deletion, email us and we'll act on it promptly.

Contact

Questions about this policy or your data: privacy@vibeopenclaw.com